返回
Substitute Meta-Learning for Black-Box Adversarial Attack
DOI:10.1109/LSP.2022.3226118.png)
摘要
En 中文
Adversarial examples have raised great concerns about the security of deep learning models. Substitute training makes it possible to conduct black-box substitute attacks in real-world scenarios where the attacker does not need access to the structure, parameters, and training set of the target model. However, existing substitute training methods require a large number of queries on the target model and suffer from low attack success rates. To alleviate these problems, we propose a novel black-box adversarial attack method, named substitute meta-learning (SML), which combines meta-learning with the training of the substitute model. Different from existing substitute training methods that rely on data augmentation tactics or refined loss functions, we aim to boost the learning efficiency of the substitute model to improve training efficiency and attack performance. Specifically, we introduce meta-learning to enable the substitute model to learn the knowledge of the target model using a few queries. Extensive experiments are conducted on MNIST and CIFAR-10 datasets. The experimental results show that the proposed SML can improve the attack success rate from 46.1% to 61.3% while requiring fewer queries.
Keyword:
Adversarial example
black-box attack
deep neural networks
meta-learning
substitute training
期刊
IF:
9.6
论文数:
1.1W
被引数:
1.7W
机构
引用论文
Enhanced Reactivity of Dinuclear Copper(I) Acetylides in Dipolar Cycloadditions偶极环加成反应中双核乙炔铜 (I) 的反应性增强
Gradient-based learning applied to document recognition基于梯度的学习在文档识别中的应用
PROCEEDINGS OF THE IEEE
IF25.9

